{
  "osquery_time": "1592478128",
  "datetime": "2020-06-05T16:12:02.4523553Z",
  "source": "Security",
  "provider_name": "Microsoft-Windows-Security-Auditing",
  "provider_guid": "{54849625-5478-4994-a5ba-3e3b0328c30d}",
  "event_id": "4624",
  "task_id": "12544",
  "level": "0",
  "keywords": "0x8020000000000000",
  "data": "{\"EventData\":{\"SubjectUserSid\":\"S-1-5-18\",\"SubjectUserName\":\"DESKTOP-4AR7BIA$\",\"SubjectDomainName\":\"WORKGROUP\",\"SubjectLogonId\":\"0x3e7\",\"TargetUserSid\":\"S-1-5-18\",\"TargetUserName\":\"SYSTEM\",\"TargetDomainName\":\"NT AUTHORITY\",\"TargetLogonId\":\"0x3e7\",\"LogonType\":\"5\",\"LogonProcessName\":\"Advapi  \",\"AuthenticationPackageName\":\"Negotiate\",\"WorkstationName\":\"-\",\"LogonGuid\":\"{00000000-0000-0000-0000-000000000000}\",\"TransmittedServices\":\"-\",\"LmPackageName\":\"-\",\"KeyLength\":\"0\",\"ProcessId\":\"0x284\",\"ProcessName\":\"C:\\\\Windows\\\\System32\\\\services.exe\",\"IpAddress\":\"-\",\"IpPort\":\"-\",\"ImpersonationLevel\":\"%%1833\",\"RestrictedAdminMode\":\"-\",\"TargetOutboundUserName\":\"-\",\"TargetOutboundDomainName\":\"-\",\"VirtualAccount\":\"%%1843\",\"TargetLinkedLogonId\":\"0x0\",\"ElevatedToken\":\"%%1842\"}}",
  "computer_name": "DESKTOP-4AR7BIA"
}
